CVE-2019-3681
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
29/06/2020
Last modified:
09/07/2020
Description
A External Control of File Name or Path vulnerability in osc of SUSE Linux Enterprise Module for Development Tools 15, SUSE Linux Enterprise Software Development Kit 12-SP5, SUSE Linux Enterprise Software Development Kit 12-SP4; openSUSE Leap 15.1, openSUSE Factory allowed remote attackers that can change downloaded packages to overwrite arbitrary files. This issue affects: SUSE Linux Enterprise Module for Development Tools 15 osc versions prior to 0.169.1-3.20.1. SUSE Linux Enterprise Software Development Kit 12-SP5 osc versions prior to 0.162.1-15.9.1. SUSE Linux Enterprise Software Development Kit 12-SP4 osc versions prior to 0.162.1-15.9.1. openSUSE Leap 15.1 osc versions prior to 0.169.1-lp151.2.15.1. openSUSE Factory osc versions prior to 0.169.0 .
Impact
Base Score 3.x
9.80
Severity 3.x
CRITICAL
Base Score 2.0
6.40
Severity 2.0
MEDIUM
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:opensuse:osc:*:*:*:*:*:*:*:* | 0.169.1-3.20.1 (excluding) | |
cpe:2.3:o:suse:linux_enterprise_server:15:*:*:*:*:*:*:* | ||
cpe:2.3:a:opensuse:osc:*:*:*:*:*:*:*:* | 0.162.1-15.9.1 (excluding) | |
cpe:2.3:o:suse:linux_enterprise_software_development_kit:12:sp5:*:*:*:*:*:* | ||
cpe:2.3:a:opensuse:osc:*:*:*:*:*:*:*:* | 0.162.1-15.9.1 (excluding) | |
cpe:2.3:o:suse:linux_enterprise_software_development_kit:12:sp4:*:*:*:*:*:* | ||
cpe:2.3:a:opensuse:osc:*:*:*:*:*:*:*:* | 0.169.1-lp151.2.15.1 (excluding) | |
cpe:2.3:o:opensuse:leap:15.1:*:*:*:*:*:*:* | ||
cpe:2.3:a:opensuse:osc:*:*:*:*:*:*:*:* | 0.169.0 (excluding) | |
cpe:2.3:a:opensuse:factory:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page